|
|
Log in / Subscribe / Register

curl: multiple vulnerabilities

Package(s):curl CVE #(s):CVE-2016-8615 CVE-2016-8616 CVE-2016-8617 CVE-2016-8618 CVE-2016-8619 CVE-2016-8620 CVE-2016-8621 CVE-2016-8622 CVE-2016-8623 CVE-2016-8624
Created:November 2, 2016 Updated:November 18, 2016
Description: From the SUSE advisory:

- CVE-2016-8624: invalid URL parsing with '#' (bsc#1005646)

- CVE-2016-8623: Use-after-free via shared cookies (bsc#1005645)

- CVE-2016-8622: URL unescape heap overflow via integer truncation (bsc#1005643)

- CVE-2016-8621: curl_getdate read out of bounds (bsc#1005642)

- CVE-2016-8620: glob parser write/read out of bounds (bsc#1005640)

- CVE-2016-8619: double-free in krb5 code (bsc#1005638)

- CVE-2016-8618: double-free in curl_maprintf (bsc#1005637)

- CVE-2016-8617: OOB write via unchecked multiplication (bsc#1005635)

- CVE-2016-8616: case insensitive password comparison (bsc#1005634)

- CVE-2016-8615: cookie injection for other servers (bsc#1005633)

Alerts:
openSUSE openSUSE-SU-2016:2768-1 curl 2016-11-10
Fedora FEDORA-2016-e8e8cdb4ed curl 2016-11-06
Ubuntu USN-3123-1 curl 2016-11-03
Slackware SSA:2016-308-01 curl 2016-11-03
Debian DSA-3705-1 curl 2016-11-03
SUSE SUSE-SU-2016:2714-1 curl 2016-11-03
Arch Linux ASA-201611-9 libcurl-gnutls 2016-11-03
Arch Linux ASA-201611-8 libcurl-compat 2016-11-03
Arch Linux ASA-201611-10 lib32-libcurl-gnutls 2016-11-03
Arch Linux ASA-201611-5 lib32-libcurl-compat 2016-11-02
Arch Linux ASA-201611-4 lib32-curl 2016-11-02
Arch Linux ASA-201611-7 curl 2016-11-03
SUSE SUSE-SU-2016:2700-1 curl 2016-11-02
SUSE SUSE-SU-2016:2699-1 curl 2016-11-02
Gentoo 201701-47 curl 2017-01-19
Fedora FEDORA-2016-89769648a0 curl 2016-11-19
Debian-LTS DLA-711-1 curl 2016-11-17

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds